Describes an active campaign using help desk impersonation via Teams to deploy SNOW malware, with detailed TTPs including LSASS extraction, Pass-The-Hash, and lateral movement to domain controllers.
Describes a new privilege escalation technique in Windows RPC that could allow attackers to gain SYSTEM privileges on fully patched systems, increasing risk of lateral movement and domain compromise.
This alert describes a novel social engineering technique using Microsoft Teams to bypass MFA and gain initial access, which is directly applicable to the company's tech stack.